Node.js Experimental Permission Model Vulnerabilities Identified

Node.js Experimental Permission Model Vulnerabilities Identified

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 44.0

Article Content

Browse articles
ThreatCluster

Two vulnerabilities have been identified in the experimental permission model of Node.js 20 and 21. CVE-2024-21890 reveals that wildcards in file paths can lead to unintended access, while CVE-2024-21896 allows for path traversal attacks through monkey-patching Buffer internals. These issues affect all users utilizing the experimental feature.

Timeline

2024-02-20
CVE-2024-21890 published
2024-02-20
CVE-2024-21896 published
2026-02-18
Information published about vulnerabilities